CMMC Self-Assessment vs C3PAO: Which Path Applies and How SPRS Works

CMMC Self-Assessment vs C3PAO: Which Path Applies and How SPRS Works

Compare CMMC Level 2 self-assessment and C3PAO assessment, check your contract, and use the right SPRS assessment and affirmation workflow.

Deep Fathom Updated Last verified

A contractor performs its own CMMC Level 2 self-assessment, while a C3PAO performs a Level 2 certification assessment. Both assess the same 110 NIST SP 800-171 Revision 2 requirements, and both require the organization’s Affirming Official to affirm compliance in SPRS. As of September 30, 2026, the Phase II suspension limits new CMMC designations to self-assessment levels. Check the actual solicitation, contract and all applicable amendments before choosing a path. A separate NIST Basic assessment score does not establish CMMC status.

CMMC Level 2 self-assessment vs C3PAO assessment

The distinction is who assesses the implementation and how the results reach SPRS. 32 CFR 170.16 governs Level 2 self-assessment. Section 170.17 governs Level 2 certification assessment.

DecisionLevel 2 (Self)Level 2 (C3PAO)
Who performs the assessment?The contractorAn authorized or accredited C3PAO
What is assessed?110 NIST SP 800-171 Rev 2 requirementsThe same 110 requirements
Where do results go?The contractor submits results in SPRSThe C3PAO submits results in CMMC eMASS for transmission to SPRS
How often is a new assessment required?Every three yearsEvery three years
Who affirms compliance?The organization’s Affirming Official, after assessment and annuallyThe organization’s Affirming Official, after assessment and annually
Who closes an eligible POA&M?The contractor, through a closeout self-assessmentA C3PAO, through a closeout certification assessment

Under 32 CFR 170.21, a conditional status requires a score of at least 88 and permits only eligible requirements on the POA&M. Closeout is due within 180 days. An annual affirmation does not extend that deadline.

A self-assessment is sufficient for a Level 2 (Self) designation when the required status and affirmation are current for the applicable scope. It does not satisfy a Level 2 (C3PAO) designation. The July 13 implementing memo directs removal of C3PAO and DIBCAC designations through solicitation amendments and contract modifications. Check that your document has actually been amended or modified. The CMMC pause guide explains that document review.

Which SPRS record does your contract need?

Read the clause and the fill-in before opening SPRS. DFARS 252.204-7021 requires a current CMMC status and annual affirmation when the contract designates a CMMC level. Older solicitations or contracts may still use the NIST SP 800-171 assessment clauses. The two records answer different questions.

RecordWhat it recordsWho signs or affirms it
NIST SP 800-171 DoD AssessmentA Basic, Medium, or High assessment score for the covered contractor information systemFollow the clause and SPRS workflow for that assessment
CMMC Level 2 (Self)Requirement-level results for the 110 Rev 2 requirements, a CMMC status, and the annual affirmationThe organization’s Affirming Official in SPRS

The current DoW CMMC page says that, during the Phase II suspension, new CMMC designations are limited to Level 1 (Self) and Level 2 (Self). That does not erase a clause in an unamended document. Ask the contracting officer which record governs the award.

How do you enter a NIST SP 800-171 Basic self-assessment in SPRS?

Use this path only where the incorporated solicitation or contract requires a NIST SP 800-171 assessment record. The May 2026 SPRS Awardee Guide says the NIST assessment tab supports DFARS 252.240-7997 and, previously, DFARS 252.204-7019 and 252.204-7020. It is a separate workflow from CMMC assessment and affirmation.

  1. In PIEE, open Cyber Reports (CMMC & NIST) and select the relevant CAGE and hierarchy.
  2. Open NIST SP 800-171 Assessments, select the Basic sub-tab, and choose Add New NIST Assessment. The vendor-maintained assessment type is Basic.
  3. Enter the required assessment information and save it. The guide identifies the assessment date, score, scope, included CAGE codes, and SSP information among the recorded summary fields.
  4. Use Open CAGE Hierarchy or the CAGE field to select included CAGE codes. The guide says those CAGE codes must be in the current hierarchy.
  5. When updating a saved record, overwrite the information and select Update. Do not assume this NIST Basic entry carries a CMMC annual affirmation.

How do you enter a CMMC Level 2 self-assessment in SPRS?

  1. Get the SPRS Cyber Vendor User role in PIEE. The official Quick Entry Guide identifies that role as the permission to enter CMMC assessment information.
  2. In PIEE, open SPRS, then Cyber Reports (CMMC & NIST). Select the hierarchy identified by the higher-level organization.
  3. Open CMMC Assessments, select CMMC Level 2 (Self), and choose Add New Level 2 CMMC Self-Assessment.
  4. Enter the assessment details and answer the requirement-level compliance status. SPRS requires complete requirement answers before the record can proceed.
  5. Add the assessment scope, employee count, and included CAGE codes. Confirm that the CAGE hierarchy reflects the systems and entities the assessment covers.
  6. Review the calculated status. The guide states that scores of 88 through 109 can be Conditional and 110 can be Final, provided the POA&M rules are met.
  7. Transfer the record to the Affirming Official if the entry user is not that person. The Affirming Official reviews the statement and selects Affirm.
  8. Calendar the annual affirmation. DFARS 252.204-7021 requires annual affirmations for each applicable CMMC UID.

What does the Affirming Official attest to?

The affirmation is a statement of continuous compliance tied to the CMMC status. Under 32 CFR 170.22, it is made by an Affirming Official after the assessment and annually thereafter. Build the review around current evidence, the system security plan, the CAGE codes in scope, and any open POA&M. The official should be able to explain what changed since the last assessment before affirming.

Can you edit an assessment or cover multiple companies?

The Quick Entry Guide says a Cyber Vendor User can edit, cancel, or delete certain CMMC status types. Preserve the reason, affected scope, and approval record before changing an entry. The guide also says CAGE hierarchy data comes from SAM and users cannot add CAGE codes outside their company hierarchy. If two companies are separate hierarchies, do not assume one entry covers both. Confirm the applicable systems, legal entities, and CAGE relationships before submission.

Records to retain before submission

Retain the SSP, assessment evidence, scope statement, CAGE list, POA&M where allowed, submission date, CMMC UID, and affirmation record. Read how to write an SSP, prepare for a CMMC assessment, and the assessment timeline before the review. Deep Fathom can organize the requirement, assigned work, evidence, and review record. Your Affirming Official still makes the statement to the government.

Don’t merge separate legal entities because their names look alike. Don’t affirm until the scope record and evidence review agree. See the Level 1 guide for the separate Level 1 path.

Sources
SourceWhat it supports
SPRS Quick Entry GuidePIEE role, navigation, entry fields, score states, and affirmation workflow.
DFARS 252.204-7021Contract-level CMMC status, UID, and annual affirmation obligations.
32 CFR Part 170CMMC assessment and affirmation rules.